CVE-2025-3840 – Oracle OVA Connect Installer Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-3840 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by bd8dbf88-98d9-42c6-be08-cf8e48a32093 Apr. 21, 2025 Action […]
CVE-2025-3837 – “VMware End of Life OVA Connect Remote Code Execution Vulnerability”
CVE ID : CVE-2025-3837 Published : April 21, 2025, 10:15 a.m. | 2 hours, 10 minutes ago Description : An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end […]
CVE-2025-3838 – “VMware Connect Unauthorized Access to Installer Credentials”
CVE ID : CVE-2025-3838 Published : April 21, 2025, 10:15 a.m. | 2 hours, 10 minutes ago Description : An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to […]
⚡ THN Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & More
⚡ THN Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & More Cybersecurity / Hacking News Can a harmless click really lead to a full-blown cyberattack? Surprisingly, yes — and that’s exactly what we saw in last week’s activity. Hackers are getting better at hid … Read more Published Date: Apr 21, 2025 […]
Speedify VPN macOS Vulnerability Let Attackers Escalate Privilege
Speedify VPN macOS Vulnerability Let Attackers Escalate Privilege A significant security vulnerability, tracked as CVE-2025-25364, was discovered in Speedify VPN’s macOS application, exposing users to local privilege escalation and full system compromise. The flaw, … Read more Published Date: Apr 21, 2025 (50 minutes ago) Vulnerabilities has been mentioned in this article.
Critical PyTorch Vulnerability Let Attackers Execute Remote Code
Critical PyTorch Vulnerability Let Attackers Execute Remote Code A critical vulnerability in PyTorch that allows attackers to execute malicious code remotely, even when using safeguards previously thought to mitigate such risks. The vulnerability, identified as CVE … Read more Published Date: Apr 21, 2025 (1 hour, 13 minutes ago) Vulnerabilities has been mentioned in this article.
Critical ASUS Router Vulnerability Let Attackers Malicious Code Remotely
Critical ASUS Router Vulnerability Let Attackers Malicious Code Remotely A critical security vulnerability has been discovered in ASUS routers featuring the AiCloud service, exposing millions of devices to the risk of remote code execution by unauthenticated attackers. The … Read more Published Date: Apr 21, 2025 (1 hour, 24 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-25228 – VirtueMart SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-25228 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]
Kimusky Hackers Exploiting RDP & MS Office Vulnerabilities in Targeted Attacks
Kimusky Hackers Exploiting RDP & MS Office Vulnerabilities in Targeted Attacks A sophisticated Advanced Persistent Threat (APT) operation named Larva-24005, linked to the notorious Kimsuky threat group, has been discovered actively exploiting critical vulnerabilities in Remote D … Read more Published Date: Apr 21, 2025 (30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2019-0708 […]
Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery
Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery Vulnerability / Threat Intelligence Cybersecurity researchers have disclosed a surge in “mass scanning, credential brute-forcing, and exploitation attempts” originating from IP addresses associated wi … Read more Published Date: Apr 21, 2025 (1 hour, 14 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-0108 […]